Search/CVE-2022-40703
CVE — Medium

CVE-2022-40703

CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.

CVSS v3.1
5.2 MEDIUM
EPSS
0.32%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorPHYSICAL
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
ConfidentialityLOW
IntegrityHIGH
AvailabilityNONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Connections
2 relationships
Timeline
disclosure → media coverage
Oct 26, 2022
Disclosure — published as a CVE record. · last revised by NVD Nov 21, 2024